Vulnerabilities > CVE-2002-1239 - Unspecified vulnerability in QNX Rtos 6.2.0

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
qnx
exploit available

Summary

QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised privileges, which allows local users to gain privileges by modifying the PATH to point to a malicious cp program.

Vulnerable Configurations

Part Description Count
Application
Qnx
1

Exploit-Db

descriptionQNX RTOS 6.2 Application Packager Non-Explicit Path Execution Vulnerability. CVE-2002-1239. Local exploit for linux platform
idEDB-ID:22002
last seen2016-02-02
modified2002-11-08
published2002-11-08
reporterTexonet
sourcehttps://www.exploit-db.com/download/22002/
titleQNX RTOS 6.2 Application Packager Non-Explicit Path Execution Vulnerability